PLUGIN SECURITY
Is Internal Link Juicer safe?
Improve your SEO and your user experience through internal linkbuilding. Automated links between your posts based on a smart keyword configuration.
What this plugin does
- Slug:
internal-links - Author: David Anderson / Team Updraft
- 90000+ active installs
- 94/100 rating (534 reviews on wordpress.org)
- 1501298 all-time downloads
- On WordPress.org since 2018-09-22
automatic linkinginternal linkslinkbuildingonpageseo
Maintenance status
- Latest known version: 2.26.0
- Last updated: 2026-08-13 11:16am GMT
- Tested up to WordPress: 7.1
- Requires PHP: 7.1.0+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
4 known CVEs on file for Internal Link Juicer. Reported between 2022 and 2026.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2024-13362 | Internal Link Juicer: SEO Auto Linker for WordPress [internal-links] < 2.25.2 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 2.25.2 | 2.25.2 | 2026-04-30 | ✓ fixed in latest |
| CVE-2024-37941 | Internal Link Juicer: SEO Auto Linker for WordPress [internal-links] < 2.24.4 | Cross-Site Request Forgery (CSRF) | Medium 4.3 | < 2.24.4 | 2.24.4 | 2024-07-09 | ✓ fixed in latest |
| CVE-2024-0657 | Internal Link Juicer: SEO Auto Linker for WordPress [internal-links] < 2.23.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.8 | < 2.23.5 | 2.23.5 | 2024-02-08 | ✓ fixed in latest |
| CVE-2023-33999 | Internal Link Juicer: SEO Auto Linker for WordPress [internal-links] < 2.23.2 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 2.23.3 | 2.23.3 | 2023-07-18 | ✓ fixed in latest |
| — | Internal Link Juicer: SEO Auto Linker for WordPress [internal-links] < 1.3.0 | Missing Authorization | Medium 6.3 | < 1.3.0 | 1.3.0 | 2022-03-04 | ✓ fixed in latest |
| — | Internal Link Juicer: SEO Auto Linker for WordPress [internal-links] < 1.3.0.1 | — | Unknown | < 1.3.0.1 | 1.3.0.1 | 2022-02-28 | ✓ fixed in latest |
| — | Internal Link Juicer: SEO Auto Linker for WordPress [internal-links] < 1.3.0.1 | — | Unknown | < 1.3.0.1 | 1.3.0.1 | 2022-02-28 | ✓ fixed in latest |
| — | Unauthorised AJAX Calls via Freemius | — | Unknown | < 1.3.0 | 1.3.0 | — | ✓ fixed in latest |
How to fix it
Keep Internal Link Juicer updated — 2.26.0 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Internal Links Manager — 10000+ active installs — 96/100 (33) — max PHP 8.4
- SEO Auto Linker — 1000+ active installs — 78/100 (11) — max PHP 8.4
- Automatic Internal Links for SEO by Pagup — 1000+ active installs — 60/100 (8) — max PHP 8.4
- Better Internal Link Search — 1000+ active installs — 100/100 (25)
- Link Manager – Analyze, Automate, and Monitor Links — 1000+ active installs — 88/100 (10) — max PHP 8.4
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.